{"data":{"id":"b5bd1afa-50ea-4dca-9180-61f4065ba221","title":"CVE-2026-102697: Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode…","summary":"Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization flaw in the experimental agent mode Bash tool approval mechanism, which fails to properly parse shell syntax. An attacker who can influence model output through prompt injection can append control operators such as semicolons or logical operators to an approved command, executing additional shell commands and bypassing the session approval requirement.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102697","publishedAt":"2026-09-29T17:17:08.150Z","cveId":"CVE-2026-102697","cweIds":["CWE-863"],"cvssScore":"7.8","cvssSeverity":"high","severity":"high","attackType":["prompt_injection","other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Ollama"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Ollama agent mode Bash tool approval bypass via shell operators","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"local","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00146,"epssCheckedAt":"2026-10-10T02:56:35.067Z","kevDateAdded":null,"advisoryAliases":["GHSA-44m8-pr79-3734"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:07.690Z","patchAvailable":null,"disclosureDate":"2026-09-29T17:17:08.150Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}}